Service | Microsoft Docs article | Related commit history on GitHub | Change details |
---|---|---|---|
SharePoint | Get Ready Copilot Sharepoint Advanced Management | https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/get-ready-copilot-sharepoint-advanced-management.md | Previously updated : 09/12/2024 Title: Get ready for Microsoft 365 Copilot with SharePoint Advanced Management (SAM) Last updated : 11/14/2024 + Title: Get ready for Microsoft 365 Copilot with SharePoint Advanced Management -description: "Learn how to get ready for Microsoft 365 Copilot by using SharePoint Advanced Management (SAM) to govern your organization's data effectively by controlling content sprawl, preventing oversharing, control content access by Copilot, and manage content lifecycle." +description: "Learn how to get ready for Microsoft 365 Copilot by using SharePoint Advanced Management. Use SharePoint Advanced Management to govern your organization's data effectively by controlling content sprawl, preventing oversharing, control content access by Copilot, and manage content lifecycle." -# Get ready for Microsoft 365 Copilot with SharePoint Advanced Management (SAM) +# Get ready for Microsoft 365 Copilot with SharePoint Advanced Management -## Copilot and SharePoint +## Use SharePoint to govern your organization's data effectively -Your organization is preparing to enable Microsoft 365 Copilot, an AI-driven productivity tool that enhances creativity, productivity, and skills in real-time. As the SharePoint admin, itΓÇÖs crucial to govern your organization's SharePoint data properly to ensure Copilot's results are appropriate, accurate, and compliant. Understanding the significance of content governance in SharePoint for Copilot begins with knowing [how Copilot works through three components](/copilot/microsoft-365/microsoft-365-copilot-overview#copilot-integration-with-graph-and-microsoft-365-apps): --- Large language models (LLMs)-- The Microsoft 365 productivity apps that you use every day, such as Word, Excel, PowerPoint, Outlook, Teams, and others.-- Content in Microsoft Graphs--When a user makes a request to Copilot, it processes the request using large language models (LLMs). It then generates a response with LLMs by leveraging content from Microsoft Graph and web content (optional). --Content in Microsoft Graph includes emails, files, meetings, chats, calendars, and contacts. A significant portion of them is stored as SharePoint files. When you share documents with others, these documents become data stored on SharePoint sites, document libraries and OneDrive. These documents can be: Word document shared by your colleagues, a presentation that you're working with your team, meeting recordings, project notes you created in Loop and OneNote, and more. To ensure assistance provided by Copilot is appropriate, accurate, and compliant, as your organizationΓÇÖs SharePoint admin, it's crucial for you to ensure that your organizationΓÇÖs data in SharePoint is appropriately governed from the following three aspects: +To ensure assistance provided by Copilot is appropriate, accurate, and compliant, as your organizationΓÇÖs SharePoint admin, it's crucial for you to ensure that your organizationΓÇÖs data in SharePoint is appropriately governed from the following three aspects: - **Manage content sprawl**: Reduce content duplication and ensure well-planned content creation. Ensure all sites and content are well managed governed by site owners. - **Prevent content oversharing and control content access**: Use tools available to SharePoint admins and site owners to prevent users from oversharing content. Limit content access by Copilot with user group settings, and other tools. - **Manage content lifecycle**: Remove inactive and outdated content and sites. Make sure the information Copilot access is accurate and up to date. -## Use SharePoint Advanced Management (SAM) to get your organization ready for Copilot +## Use SharePoint Advanced Management to get your organization ready for Copilot -[Microsoft SharePoint Premium ΓÇô SharePoint Advanced Management (SAM)](/sharepoint/advanced-management) is an essential Microsoft 365 add-on that helps you, as the SharePoint admin to address these three pillars around content governance. To get ready for your organizationΓÇÖs Microsoft 365 Copilot adoption, there are a few highly recommended steps you can take, primarily using SharePoint Advanced Management tools. These steps reduce accidental oversharing, minimize your content governance footprint, improve Copilot response quality, control content access by Copilot, and ensure data safety specifically for business-critical sites. Let's delve into the specific steps you can take: +[Microsoft SharePoint Premium ΓÇô SharePoint Advanced Management](/sharepoint/advanced-management) is an essential Microsoft 365 add-on that helps you, as the SharePoint admin to address these three pillars around content governance. To get ready for your organizationΓÇÖs Microsoft 365 Copilot adoption, there are a few highly recommended steps you can take, primarily using SharePoint Advanced Management tools. These steps reduce accidental oversharing, minimize your content governance footprint, improve Copilot response quality, control content access by Copilot, and ensure data safety specifically for business-critical sites. Let's delve into the specific steps you can take: ### Step 1: Reduce accidental oversharing with SharePoint sharing settings To minimize accidental content oversharing via Copilot results, it's crucial to **At the organization level**: -- Update [sharing link defaults for your tenant ](/sharepoint/turn-external-sharing-on-or-off#file-and-folder-links) for your tenant from organization-wide sharing to specific people links.-- Consider hiding broad-scope permissions from your end users to reduce risks around accidental misuse. [This example](/powershell/module/sharepoint-online/set-spotenant) hides "Everyone Except External Users" in the People Picker control so that no end user can use it.+- Update [sharing link defaults for your organization ](/sharepoint/turn-external-sharing-on-or-off#file-and-folder-links) for your organization from organization-wide sharing to specific people links. +- To reduce risks around accidental misuse, consider hiding broad-scope permissions from your end users. [This example](/powershell/module/sharepoint-online/set-spotenant) hides "Everyone Except External Users" in the People Picker control so that no end user can use it. **At the site level**: Identify inactive sites, then take action to reduce your governance footprint an - If the site owners confirm the sties aren't needed, you need to put the sites either in [read-only mode](/sharepoint/site-lifecycle-management#read-only-mode). These sites will be moved to [Microsoft 365 Archive](/microsoft-365/archive/archive-overview) after a configurable duration (3, 6, 9, or 12 months). > [!TIP]-> Sites moved to Microsoft 365 Archive are no longer accessible by anyone in the organization outside of Microsoft Purview or admin search. This means Copilot won't include content from these sites when responding to user prompts. If you want to keep the site in case you need to retrieve its content later, use Inactive sites - Archive. +> Sites moved to Microsoft 365 Archive are no longer accessible by anyone in the organization outside of Microsoft Purview or admin search. This means Copilot won't include content from these sites when responding to user prompts. ### Step 4: Identify sites with potentially overshared content -Without looking at the actual content, how do you quickly identify sites with potentially overshared content? Usually, if you see there's content on a site that is being shared with one of the following options: ΓÇ£**Everyone Except External Users**ΓÇ¥, ΓÇ£**People in your organization**ΓÇ¥ and ΓÇ£**Anyone**ΓÇ¥, there's a bigger chance that the content is overshared. Currently, SAM activity based reports let you quickly identify most actively overshared sites, by running three individual reports: +How do you quickly identify sites with potentially overshared content without looking at the actual site? Usually, if you see there's content on a site that is being shared with one of the following options: ΓÇ£**Everyone Except External Users**ΓÇ¥, ΓÇ£**People in your organization**ΓÇ¥ and ΓÇ£**Anyone**ΓÇ¥, there's a bigger chance that the content is overshared. Currently, SharePoint Advanced Management activity based reports let you quickly identify most actively overshared sites, by running three individual reports: - [Usage of "Everyone Except External Users"](/sharepoint/data-access-governance-reports#content-shared-with-everyone-except-external-users-eeeu-reports) - [Usage of ΓÇ£People in your organization" sharing links](/sharepoint/data-access-governance-reports#sharing-links-reports) Sites with these three types of usage are at a greater risk of oversharing compa ### Step 5: Control access to content -When you use Microsoft Copilot, the results come from content in Microsoft Graph, based on each individual userΓÇÖs profile and permissions. In Step 3, you have identified sites with potentially overshared content. Next, you want to ensure Copilot only has access to content when appropriate. Currently, you can initiate a Site Access Review for site owners to confirm overshared content and take remediation steps. Meanwhile, you as the SharePoint admin can use the Restricted Access Control Policy to restrict access to a site with overshared content. +When you use Microsoft Copilot, the results come from content in Microsoft Graph, based on each individual userΓÇÖs profile and permissions. In Step 3, you identify sites with potentially overshared content. Next, you want to ensure Copilot only has access to content when appropriate. Currently, you can initiate a Site Access Review for site owners to confirm overshared content and take remediation steps. Meanwhile, you as the SharePoint admin can use the Restricted Access Control Policy to restrict access to a site with overshared content. #### Site access reviews by site owners - For any site that is identified with potentially overshared content, [Site Access Review](/sharepoint/site-access-review) is needed. As the SharePoint Admin, you should [initiate the Site Access Review](/sharepoint/site-access-review/#initiate-a-site-access-review). - Site Owners [receive notification](/sharepoint/site-access-review#site-access-review-process-for-site-owners) for each site that requires attention. They can use the [**Site reviews page**](/sharepoint/site-access-review#manage-multiple-site-access-review-requests-for-site-owners) to track and manage multiple review requests.-- The site owner [reviews access in two main areas](/sharepoint/site-access-review#review-everyone-except-external-users-site-access-review-requests-for-site-owners): SharePoint groups and individual items to determine whether the broad sharing is appropriate, or it is indeed oversharing and requires remediation. +- The site owner [reviews access in two main areas](/sharepoint/site-access-review#review-everyone-except-external-users-site-access-review-requests-for-site-owners): SharePoint groups and individual items to determine whether the broad sharing is appropriate, or it's indeed oversharing and requires remediation. - If the site owner determines that the content is indeed overshared, they can take easy remediation actions by using the Access Review dashboard to update permissions. #### Restrict access with the Restricted Access Control Policy -Until the Site Access Review is complete, you as the SharePoint Admin may want to take action to mitigate oversharing risks. To restrict access to a site with overshared content, the SharePoint Admin can set up a [Restricted Access Control Policy](/sharepoint/restricted-access-control). As a result, all access to the site is restricted to only the group of users specified in the policy. Accordingly, the content from this site is visible in Microsoft 365 Copilot *only for this restricted group of users*. You can restrict access to individual sites or OneDrive. +Until the Site Access Review is complete, you as the SharePoint Admin can take action to mitigate oversharing risks. To restrict access to a site with overshared content, the SharePoint Admin can set up a [Restricted Access Control Policy](/sharepoint/restricted-access-control). As a result, all access to the site is restricted to only the group of users specified in the policy. Accordingly, the content from this site is visible in Microsoft 365 Copilot *only for this restricted group of users*. You can restrict access to individual sites or OneDrive. ### Step 6: Take proactive measures on business-critical sites For business-critical sites, you want to take proactive measures to ensure the c > [!IMPORTANT] > The following policies are currently in preview and will soon be generally available. [*Sign up to participate in the preview by following instructions here*](https://forms.office.com/pages/responsepage.aspx?id=v4j5cvGGr0GRqy180BHbRw8ueKeaH4JIsskRInqtJE5UNjhYVkg5NDRNWkMxRlI0TFVDR0FYSUNGUi4u&route=shorturl). -### Use the Oversharing Baseline Report for Sites, OneDrives, and Files policy to identify oversharing risks +### Use the Oversharing Baseline Report for Sites, OneDrive, and Files policy to identify oversharing risks -In Step 4, we discussed how to run three usage reports to identify potentially overshared content. Coming soon, you'll be able to Run a single report to learn where content overexposure risk exists in all sites on your tenant, regardless of site activities. +In Step 4, we discussed how to run three usage reports to identify potentially overshared content. Coming soon, you're able to Run a single report to learn where content overexposure risk exists in all sites on your organization, regardless of site activities. -- You'll be able to start with running an ΓÇ£Oversharing Baseline Report for Sites, OneDrives and FilesΓÇ¥ report from the Data Access Governance (DAG) PowerShell commands in SharePoint Online PowerShell module. This report scans all sites in your tenant, and lists sites that share content with more than a specified number of users (you specify the number).+- You're able to start with running an ΓÇ£Oversharing Baseline Report for Sites, OneDrive and FilesΓÇ¥ report from the Data Access Governance (DAG) PowerShell commands in SharePoint Online PowerShell module. This report scans all sites in your organization, and lists sites that share content with more than a specified number of users (you specify the number). - You can sort, filter or download the report, and identify the sites with potentially overshared content. ### Use the Restricted Content Discoverability policy to further control accidental content discoverability -In Step 5 ΓÇö **control access to content**, it's advised to begin with the Site Access Review policy to verify if the potentially overshared content identified in Step 3 is truly overshared. Following this, apply the Restricted Access Control policy to limit access to designated user groups. Soon, a new policy, the Restricted Content Discoverability policy, will be available to further control accidental content discoverability. +In Step 5 ΓÇö **control access to content**, we suggest you begin with the Site Access Review policy to verify if the potentially overshared content identified in Step 3 is truly overshared. Following this, apply the Restricted Access Control policy to limit access to designated user groups. Soon, a new policy, the Restricted Content Discoverability policy, will be available to further control accidental content discoverability. In addition, in Step 6, to further protect content on your business-critical sites, you can use Restricted Content Discoverability to leave permissions in place, but prevent the content from being available to Microsoft 365 Copilot and Organization-wide search experiences. The Restricted Content Discoverability policy leaves site access unchanged but p ### Use AI Powered Semantic matching to find similar sites -You discovered a site containing crucial business data that lacks proper protection. Are there more sites like this one that might have similar vulnerabilities? Soon, AI Powered Semantic matching helps you locate these sites using the site you discovered as the example. The AI powered semantic matching tool reads through all the sites you have, including content, files, metadata, and give you a list of similar sites based on your example site. +You discovered a site containing crucial business data that lacks proper protection. Are there more sites like this one that might have similar vulnerabilities? Soon, AI Powered Semantic matching helps you locate these sites using the site you discovered as the example. The AI powered semantic matching tool reads through all the sites you have, including content, files, metadata, and give you a list of similar sites based on your example site. |
SharePoint | Manage Site Collection Administrators | https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/manage-site-collection-administrators.md | Previously updated : 03/18/2024 Last updated : 11/14/2024 Title: "Manage site admins" description: "Learn how global and SharePoint admins can add and remove site adm # Manage site admins -This article describes how a [SharePoint Administrator](/sharepoint/sharepoint-admin-role) and [above](/microsoft-365/admin/add-users/about-admin-roles) in Microsoft 365 can add and remove site admins (previously called "site collection admins"). If you're an owner of a communication site, or a site that belongs to a Microsoft 365 group, see [Manage your SharePoint site settings](https://support.office.com/article/8376034d-d0c7-446e-9178-6ab51c58df42#__BKMKMngSitePermissions) for info about giving people access to your site. If you're an admin for a classic site, see [Manage your SharePoint site settings](https://support.office.com/article/8376034d-d0c7-446e-9178-6ab51c58df42#id0eaabaaa=server). +This article describes how a [SharePoint Administrator](/sharepoint/sharepoint-admin-role) and [above](/microsoft-365/admin/add-users/about-admin-roles) in Microsoft 365 can add and remove [site admins](/sharepoint/site-permissions#site-admins) (previously called "site collection admins"). If you're an owner of a communication site, or a site that belongs to a Microsoft 365 group, see [Manage your SharePoint site settings](https://support.office.com/article/8376034d-d0c7-446e-9178-6ab51c58df42#__BKMKMngSitePermissions) for info about giving people access to your site. If you're an admin for a classic site, see [Manage your SharePoint site settings](https://support.office.com/article/8376034d-d0c7-446e-9178-6ab51c58df42#id0eaabaaa=server). > [!NOTE] > If you're a Global Administrator and want info about assigning other users the SharePoint Administrator role in Microsoft 365, see [Assigning admin permissions](/office365/admin/add-users/assign-admin-roles).Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role. ## Add or remove site admins in the new SharePoint admin center -By using the new<a href="https://go.microsoft.com/fwlink/?linkid=2185219" target="_blank">SharePoint admin center</a>, you can change the owners for sites that use the new team site and communication site templates. You can also add and remove group members in the Microsoft 365 admin center. For info, see [Add or remove members from Microsoft 365 groups](/office365/admin/create-groups/add-or-remove-members-from-groups). +By using the new <a href="https://go.microsoft.com/fwlink/?linkid=2185219" target="_blank">SharePoint admin center</a>, you can change the owners for sites that use the new team site and communication site templates. You can also add and remove group members in the Microsoft 365 admin center. For info, see [Add or remove members from Microsoft 365 groups](/office365/admin/create-groups/add-or-remove-members-from-groups). 1. Go to <a href="https://go.microsoft.com/fwlink/?linkid=2185220" target="_blank">**Active sites** in the SharePoint admin center</a>, and sign in with an account that has [admin permissions](./sharepoint-admin-role.md) for your organization. |
SharePoint | Onedrive Document Translation | https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/onedrive-document-translation.md | + + Title: Translate documents in OneDrive ++++ Last updated : 11/13/2024+audience: admin +++search.appverid: ++ - enabler-strategic +ms.localizationpriority: medium +description: Learn about the document translation service in OneDrive. +++# Translate documents in OneDrive ++> [!NOTE] +> Through June 2025, you can try out document translation and other selected Microsoft Syntex services at no cost if you have [pay-as-you-go billing](/microsoft-365/syntex/syntex-azure-billing) set up. For details on how to get started and the limitations, see [Try out Microsoft Syntex and explore its services](/microsoft-365/syntex/promo-syntex). ++OneDrive, powered by Microsoft Syntex, allows you to translate documents while preserving the original format and structure. With this feature, you can create a translated copy of a single file or a set of files. The translation feature is available for all supported languages and dialects. +++++## Key features ++- **Manual or automatic translation**: You can manually translate files or set up a rule for automatic translation. +- **Translation of different file types**: Translate various file types, including .docx, .pdf, .pptx, and more. +- **Video transcripts and captions**: The translation feature also supports translating video transcripts and closed caption files. For more information, see [Transcript Translations in Stream for SharePoint](https://support.microsoft.com/office/microsoft-syntex-pay-as-you-go-transcript-translations-in-stream-for-sharepoint-2e34ad1b-e213-47ed-a806-5cc0d88751de). ++++## Requirements and limitations ++### Supported file types ++Document translation is available for the following file types: ++- `.csv`, `.docx`, `.htm`, `.html`, `.markdown`, `.md`, `.msg`, `.pdf`, `.pptx`, `.txt`, `.xlsx` ++For legacy file formats, the translated copy is created in the modern equivalent: ++- `.doc` → `.docx` +- `.xls` → `.xlsx` +- `.ppt` → `.pptx` ++> [!NOTE] +> SharePoint site pages are not supported for translation at this time. ++### Supported file size ++The maximum file size for translation is 40 MB. ++### Supported languages ++Translation in Syntex is available for all supported languages and dialects. +++++## Current limitations ++- **Images**: Text embedded in images within documents isn't translated. +- **Encrypted files**: Encrypted files can't be translated. +- **Password-protected files**: Password-protected files aren't eligible for translation. +- **SharePoint libraries**: Translation actions are also available for files stored in SharePoint libraries. +- **On-demand translation for folders**: This feature will be available in a future release. ++++## Frequently asked questions ++For more information, see the following resources: ++- [Document Translation: FAQ](/azure/ai-services/translator/document-translation/faq#document-translation-faq) +- [How does Translator count characters?](/azure/ai-services/translator/translator-faq#how-does-translator-count-characters) |
SharePoint | Sharepoint Copilot Best Practices | https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/commits/public/SharePoint/SharePointOnline/sharepoint-copilot-best-practices.md | Previously updated : 02/29/2024 Last updated : 11/14/2024 Title: Microsoft 365 Copilot - best practices with SharePoint search.appverid: - MET150 description: "Learn about the best practices with SharePoint for content sharing when enabling Microsoft 365 Copilot." -# Microsoft 365 Copilot - best practices with SharePoint +# Microsoft 365 Copilot with SharePoint -Microsofts value by connecting Large Language Models (LLMs) to your organizational data. Microsoft 365 Copilot accesses content and context through [Microsoft Graph](/graph/overview) and can generate responses based on your organizational data. The data sources include user documents stored in SharePoint and OneDrive, emails, calendars, chats, meetings, and contacts. Microsoft 365 Copilot combines this content with the user’s working context, such as the meeting a user is in now, the email exchanges the user had on a topic, or the chat conversations the user had last week. Microsoft 365 Copilot uses this combination of content and context to help provide accurate, relevant, and contextual responses. +## Copilot and SharePoint -## How do SharePoint permissions affect your users’ Microsoft 365 Copilot experience? +Your organization is preparing to enable Microsoft 365 Copilot, an AI-driven productivity tool that enhances creativity, productivity, and skills in real-time. As the SharePoint admin, it’s crucial to govern your organization's SharePoint data properly to ensure Copilot's results are appropriate, accurate, and compliant. Understanding the significance of content governance in SharePoint for Copilot begins with knowing [how Copilot works through three components](/copilot/microsoft-365/microsoft-365-copilot-overview#copilot-integration-with-graph-and-microsoft-365-apps): -Microsoft 365 Copilot only surfaces organizational data to which individual users have *at least view permissions*. It's important to use the permission models in SharePoint to ensure the right users or groups have the right access to the right content within your organization. -This article provides guidance and best practices that you, as a SharePoint administrator, can take control of the SharePoint permissions model before your organization [enable Microsoft 365 Copilot for your users](/microsoft-365-copilot/microsoft-365-copilot-enable-users). +- Large language models (LLMs) +- The Microsoft 365 productivity apps that you use every day, such as Word, Excel, PowerPoint, Outlook, Teams, and others. +- Content in Microsoft Graphs -## Before enabling Microsoft 365 Copilot +Content in Microsoft Graph includes emails, files, meetings, chats, calendars, and contacts. A significant portion of them is stored as SharePoint files. When you share documents with others, these documents become data stored on SharePoint sites, document libraries and OneDrive. These documents can be: Word document shared by your colleagues, a presentation that you're working with your team, meeting recordings, project notes you created in Loop and OneNote, and more. When a user makes a request to Copilot, it processes the request using large language models (LLMs). It then generates a response with LLMs by leveraging content from Microsoft Graph and web content (optional). -Organizations operate at various levels of maturity in governing SharePoint data. While some enterprises strictly monitor permissions and oversharing of content, others don't. The situation is further complicated because many enterprises have legitimate reasons to share "some" data widely within the organization. -Sometimes, end users in your organization make choices that result in the oversharing of SharePoint content. As an example, it's noticed that end users don't always pay attention to the permissions of the site/library/folder where they're uploading files. They may end up uploading or saving business critical content in locations where other users may have access and may include external users. It's also observed that some end users tend to prefer sharing files in SharePoint with large groups rather than with individuals. This practice can result in oversharing. -Microsoft 365 Copilot utilizes all data that a user has access to, which may include broadly shared files that the user is unaware of. As a result, users might see Microsoft 365 Copilot as exposing content that was overshared. -To identify and remediate overshared content in SharePoint, follow these best practices. +Microsoft 365 Copilot only surfaces organizational data to which individual users have *at least view permissions*. It's important to use the permission models in SharePoint to ensure the right users or groups have the right access to the right content within your organization. To get ready for your organization's Microsoft 365 Copilot adoption, there are a few [highly recommended steps](/sharepoint/get-ready-copilot-sharepoint-advanced-management) you can take with SharePoint and OneDrive using [SharePoint advanced management](/sharepoint/advanced-management). In addition, as a SharePoint administrator, here are some steps you can take using regular SharePoint settings to prepare your organization for Microsoft 365 Copilot: -> [!Note] -> -> - These steps are provided exclusively for SharePoint administrators. -> - Some of the following features require a SharePoint Advance Management license. +## Step 1 - Optimize search in SharePoint -### Step 1: Review site-level sharing controls and remove "Everyone Except External Users" from people picker +✅ **Optimize your SharePoint content for search** -- Educate site admins on the site-level controls they can use to [restrict members from sharing](/microsoft-365/solutions/microsoft-365-limit-sharing#sharing-with-specific-people). One key setting here ensures that Site Owners are the recipients of [access requests](https://support.microsoft.com/office/set-up-and-manage-access-requests-94b26e0b-2822-49d4-929a-8455698654b3). -- Consider hiding broad-scope permissions from your end users to reduce risks around accidental misuse. [This example](/powershell/module/sharepoint-online/set-spotenant#example-2) hides the "Everyone Except External Users" in the People Picker control so that no end user can use it. -- Consider [adopting sharing best practices](/microsoft-365/solutions/microsoft-365-limit-sharing) like changing sharing link defaults from companywide sharing to specific people links.+As mentioned before, when a user makes a request to Copilot, it processes the request and then generates a response with LLMs. Copilot leverages content from Microsoft Graph and web content (optional). +So how does Copilot get content from SharePoint? It is the same way when a user searches for content via [SharePoint Search](/sharepoint/overview-of-search). -### Step 2: Identify inactive sites, then restrict access or delete +To get the most out of Copilot and get the best results, optimize your SharePoint content for search: -Reduce your surface area for potentially overshared content by identifying SharePoint sites that have been inactive for a long time. See how you can easily do that via the [Inactive Site Policies](/sharepoint/site-lifecycle-management#create-an-inactive-site-policy) in SharePoint Advanced Management. -You can then lock down permissions on these sites via the Restricted Access Control policy. You can also consider deleting these sites. +- [Make sure the content can be found](/sharepoint/make-sure-content-can-be-found) +- [Make sure the search results look great](/sharepoint/make-search-results-look-great) +- [Plan your content](/microsoftsearch/plan-your-content) -### Step 3: Identify potentially overshared content +## Step 2 - Prevent oversharing and control access with SharePoint and OneDrive -A SharePoint admin can run reports in the SharePoint Admin Center to discover broad sharing activity happening over the last month. [SharePoint Advanced Management’s](/sharepoint/advanced-management) new [data access governance reports](/sharepoint/data-access-governance-reports) can help here. A SharePoint admin can run reports on: +To prevent oversharing and control access with SharePoint and OneDrive, there are a few [highly recommended steps you can take with SharePoint and OneDrive](/sharepoint/get-ready-copilot-sharepoint-advanced-management). In addition, you can use some SharePoint built-in features to reduce oversharing and check permissions and site access in the SharePoint admin center. -- Usage of "Everyone Except External Users" in the last 28 days-- Usage of broad org-wide ["People in your organization" sharing links](/sharepoint/shareable-links-anyone-specific-people-organization) in the last 28 days-- Usage of "Anyone" sharing links in the last 28 days+To start, you can: -These reports can be downloaded as CSV files. You can also build your own report by using [Microsoft Graph Data Connect for SharePoint](/graph/data-connect-datasets#onedrive-and-sharepoint-online). +✅ **Reduce accidental oversharing with SharePoint sharing settings** -### Step 4: Take remediation actions to address oversharing +To minimize accidental content oversharing with Copilot results, implement sharing settings at the organization and site levels: -Once you have identified the SharePoint sites with potential oversharing issues, it's time to act. Your actions should consider several factors, including data sensitivity, the severity of the oversharing, and the need to maintain business operations. These actions include: +1. At the organization level: -1. For content that has been overshared and needs immediate action: - 1. The SharePoint admin should configure [Restricted Access Control Policy](/sharepoint/restricted-access-control) for such sites. As a result, all existing access to the site is restricted to only the group of users configured by the admin. Accordingly, the content from this site is visible in the Microsoft 365 Copilot experience only for this restricted group of users. This policy works for both OneDrive and SharePoint. - 1. For high-profile instances, you may want to determine who/how/when the oversharing took place. Use the [Change History](/sharepoint/change-history-report) feature to see what changes may have contributed to the oversharing. -1. For cases where SharePoint admin needs to consult with site owners/admins for action: - 1. The SharePoint admin can reach out to the owners of sites identified in data access governance reports. SharePoint admin can advise site owners on the overshared files/folders in that site and request them to act to manually remove unnecessary access. - 1. A new [SharePoint Advanced Management](/sharepoint/advanced-management) feature called "[Site Access Review](site-access-review.md)" allows a SharePoint admin to initiate a review from any 'Data Access Governance' report. Site owners will use a new Site Access Review UI to review broadly shared content on their side and either take remediation action to remove overly broad permissions or provide business justification to the SharePoint admin. + - Update [sharing settings for SharePoint and OneDrive](/sharepoint/turn-external-sharing-on-or-off) for your tenant from organization-wide sharing to specific people links. + - Consider hiding broad-scope permissions from your end users. For example, use the SharePoint `Set-SPOTenant` PowerShell cmdlet to [hide "Everyone Except External Users" in the People Picker control](/powershell/module/sharepoint-online/set-spotenant) so end users can't use it. + - Use [Restricted SharePoint Search (RSS)](/sharepoint/restricted-sharepoint-search) to temporarily restrict Copilot results up to 100 selected SharePoint sites. Child sites of Hub sites aren't counted toward the 100 limit. -### Step 5: Set restricted access control and block file download policies on business-critical sites + RSS gives you time to review & audit site permissions. It should be used only as a temporary solution to give your organization time to adopt Copilot. -- Use [Restricted Access Control](/sharepoint/restricted-access-control) to proactively protect against oversharing. +2. At the site level: -- Consider blocking downloads from selected sites via [a block download policy](/sharepoint/block-download-from-sites). Or specifically block the download of [Teams meetings recordings](/microsoftteams/block-download-meeting-recording).+ - Educate site admins on the site-level controls they can use to [restrict members from sharing](/sharepoint/change-external-sharing-site). + - Make sure that [Site Owners receive a request to access the site](https://support.microsoft.com/office/set-up-and-manage-access-requests-94b26e0b-2822-49d4-929a-8455698654b3). + - [Change the external sharing setting for a user's OneDrive](/sharepoint/user-external-sharing-settings). When a user saves a file to OneDrive, it's in the end user's personal storage. The user has full control over the file and can share it with others. To ensure data security, review OneDrive sharing features. -- Finally, consider applying encryption action with "extract rights" enforced on business-critical office documents. Learn more [here](/purview/ai-microsoft-purview).+✅ **Check permissions and site access in SharePoint admin center** ++To ensure data is secure, review SharePoint site access and permissions. Prioritize sites that contain sensitive information. ++1. In the [SharePoint admin center](https://go.microsoft.com/fwlink/?linkid=2185219), see **Active Sites** > select a site > **Edit** > **Settings**. ++ **Private** means that only users in your organization with access to the site can find it. **Public** (default) means anyone in your organization can find the site and access its content. ++ :::image type="content" source="media/sharepoint-active-sites-setting.png" alt-text="Screenshot showing the SharePoint admin center active sites panel." lightbox="media/sharepoint-active-sites-setting.png"::: ++1. In the **Membership** tab, review access to site owners, members, and visitors. Ensure that only the necessary users have access to the site. ++> [!IMPORTANT] +> This article mainly introduces using SharePoint built-in settings to reduce oversharing and check permissions and site access. To further enhance your organization's data governance with efficiency and at scale, consider using [SharePoint advanced management](/sharepoint/advanced-management) to monitor and manage your organization's SharePoint data. |